08 September 2026AI meeting the orgTrust and the black box

The training I ran before I cleared the path

I put a team through real training for a capability I had not secured. They came out ready and found the door locked, and the person who locked it was right to.

I put my team through real training on these tools. Not a demo and a slide pack. A proper trainer, days of hands on work, and live projects waiting for them afterwards so the learning had somewhere to go.

The thinking behind it was straightforward. Almost every AI conversation I end up in starts at the customer end. What can we launch, what goes in the app, what does the market expect us to have by now. Some of that is warranted. Much of it is the worry of being the one company with nothing to show.

I have always believed it works the other way round. A team that uses these tools daily gets sharper about what they are actually for. They find out where the thing holds up and where it falls over, which is not something a vendor deck will ever tell you. And what they eventually design for a customer comes out of something they understand rather than something they read about.

So we started inside. People came out of that training lit up. Some could already see the repetitive half of their week disappearing.

Then they sat down to start, and the tools were not available to them. Access had never been granted.

The refusal was the right call

The easy version of this story has a villain in it, and there was not one.

These tools want data. In a business like the one I was in, that data belongs to customers and it is the most regulated thing on the premises. Nobody saying no to that request is being obstructive. They are doing the job they are paid to do, which is to make sure the company is not the one explaining a breach to a regulator on a Tuesday afternoon.

The people who said no were right. That is what makes this interesting rather than merely annoying. If they had been wrong I would have had somewhere to push.

Where I got it wrong

The mistake was mine, and it was a sequencing mistake.

I bought the training before I cleared the access. I did the visible, energising part first, the part with a budget line and a date and a room full of people in it, and I left the slow permissions work until people were already sitting there waiting on it.

Enthusiasm is the cheapest thing to create in a team and the easiest to waste.

I wasted a good deal of it.

Looking back, I think that path needed four things and I had none of them lined up.

An approved tool with a contract that states plainly what happens to anything typed into it. A written answer to which categories of data people were permitted to use with it, which is a different question from whether the tool itself is approved and is the one that actually blocks work. Somewhere to run it that produces a log, so the answer to who did what is not a shrug. And a named owner, because a question belonging jointly to security, legal, IT and the business belongs to nobody.

None of that is exciting. All of it takes months. And all of it mattered more than the training, which is the part I had backwards.

The block does not do what it is meant to

There is a second thing worth saying, which is that the refusal, however justified, does not achieve what it is for.

A survey published in June by PagerDuty, conducted by Wakefield Research across 1,250 office professionals at companies above half a billion dollars in revenue, found two thirds had used AI tools they believed their own policy prohibited. Eighty eight percent had put work information into a public tool. Almost a third had put in confidential documents, financial information or company strategy. Eighty six percent of them work somewhere that already has an AI policy, and seventy seven percent believe the restrictions are limiting their professional growth.

PagerDuty sells incident management software, so read the framing with that in mind. The fieldwork was run by Wakefield and the sample is a reasonable one.

The risk did not disappear when the answer came back as no. It relocated. It went onto personal laptops and personal accounts, where there is no enterprise agreement, no retention setting, no log and nobody watching. A visible, governable risk was traded for an invisible, ungovernable one, and the trade was recorded as a control.

Microsoft and LinkedIn found the same shape in their Work Trend Index, across thirty one thousand knowledge workers in thirty one countries. Seventy eight percent of people using AI at work bring their own tools. Sixty percent of leaders worry their own leadership has no plan for it. And fifty two percent are reluctant to admit they use AI on their most important tasks, which is the one that stays with me. It is not only happening. It is happening quietly, which means the organisation cannot even learn from it.

None of this is new

In 2023 Samsung restricted generative AI on company machines after engineers pasted source code into ChatGPT, and said at the time that it was looking for ways the technology could be used safely. Apple limited internal use of ChatGPT and Copilot the same year.

The restriction shipped in days. The safe path was described as an intention.

That gap, between how fast an organisation can say no and how long it takes to build yes, is the whole problem. I fell into it from the other side. I moved fast on the part that was easy for me and slow on the part that was hard.

What shipped in the last week

This part is changing quickly enough to be worth naming precisely.

On 1 September, Anthropic released Claude Fable 5.1, positioned squarely at enterprise deployment. Alongside it came Enterprise Frontier Safeguards, which lets an organisation keep the monitoring data from agent activity inside its own AWS, Azure or Google Cloud environment, under its own encryption keys, its own access policies and its own audit logging. Rollout is phased from this autumn.

On 3 September, OpenAI released GPT-6 Astra, with unusually direct warnings from the company about its cyber capabilities at launch.

Google's Gemini Enterprise and its agent platform arrived earlier, announced at Cloud Next in April, with a financial services edition following in August.

Someone in enterprise IT will point out that customer managed encryption keys are not a new idea, and they will be right. What is new is that the containment now reaches the agent layer, which is exactly the part that was missing. The path I never cleared is turning into something a company can buy.

What I still do not know

So the jury is still out for me on the thing I actually want to know.

Was that barrier ever really technical? Or was it organisational all along, a question nobody owned, and I mistook one for the other because the technical version was the one people were willing to say out loud?

I lean towards the second, which is the uncomfortable answer, because organisational problems are the ones a commercial leader is supposed to be able to move. I did not move it, and I am not certain I tried in the right places.

If you have got past this in a company of any size, I would like to know how it actually went. Not the policy. The month by month of it.

The pointer

Microsoft and LinkedIn's 2024 Work Trend Index, 31,000 knowledge workers across 31 countries. The number worth sitting with is not the 78% bringing their own tools. It is the 52% who are reluctant to admit they use AI on their most important work.

← PreviousThe moment a forecast stops being an estimate
The newsletter

One long piece a month, and nothing else.

If this was worth your time, the monthly letter is the longer version of it.

No welcome sequence, no upsell, one email a month. Leave whenever you like.

Long formLinkedIn ThreadsX MonthlyNewsletter Raw feedRSS Short videoInstagram Short videoTikTok Short videoYouTube